NIST CSF
If you are just getting started, I recommend just reading it since it's only 32 pages long.
From the Introduction to Appendix A is 15 pages; it's not that much.
What is it?
- The CSF provides a high-level overview of cybersecurity concepts and outlines six Core functions to achieve risk management outcomes: Govern, Identify, Protect, Detect, Respond, and Recover.
- The CSF is not prescriptive, and is intended to be used with other frameworks and resources
2. Its goal is to help organizations identify and assess, prioritize, and communicate cyber risks
1. Identify and assess
1. Describe the security posture of the organization
2. Determine gaps and progress towards addressing gaps
2. Prioritize
1. Prioritize and action against cybersecurity risks in alignment with an organization's mission and governance expectations, and regulatory and legal requirements
3. Communicate
1. Provide a common language for high-level cybersecurity risk management
CSF Overview
- CSF is composed of three components:
- CSF Core
- Uses 6 functions to identify cybersecurity risk outcomes
- Intended to be understandable by executives, managers, and practitioners alike
- CSF Organizational Profiles
- Mechanisms for building an organization's profile that maps to the Core
- Can be used to understand current security posture or a desired target posture.
- CSF Tiers
- CSF Core
- Additional resources on the NIST CSF website:
- Informative References
- Real-world outcomes
- Implementation Examples
- Examples on how certain outcomes can be achieved
- Quick-Start Guides
- "A supplementary resource that gives brief, actionable guidance on specific CSF-related topics."
- Community Profiles and Organizational Profile Templates
- Informative References
- Working with cybersecurity risks
- The goals of the
The Core Functions
I found a neat GIF on LinkedIn summarizing the Core Functions and was going to link it here, but the constant animation constantly grabbed my attention and I had to get rid of it.
- There are six core Functions in the CSF:
- Govern
- The newest and most core of core functions
- It's critical to integrating the other Functions into an organization
- Built with new and reorganized categories from the other functions
3. When using the CSF 2.0 Reference Tool, you will see "Withdrawn" categories and subcategories that now match to Governance - Governance "informs how an organization will implement the other five Functions."
- The newest and most core of core functions
- Identify
- Identify and understand the cybersecurity risks for your organization
- Protect
- Safeguards to manage risk.
- Detect
- How the organization detects and analyzes attacks and breaches.
- Respond
- Incident response and mitigation
- Recover
- Restoring operation to impacted systems
- Govern
- Each core function is composed of categories and subcategories
- Categories and subcategories use shorthand identifiers
- Function.Category-Subcategory
- e.g., "GV.OV-01" would be Governance Oversight, subcategory 01
- Function.Category-Subcategory
- Categories and subcategories use shorthand identifiers
CSF Organizational Profiles
More coming...
CSF Tiers
More coming...
CSF 2.0 Reference Tool
- Contains a full list of functions, categories, and subcategories
- Also lists one or more Implementation examples per subcategory
- Items that were changed between CSF 1.1 and 2.0 are highlighted and detailed
- Allows you to easily search, filter, and export functions and categories
- Can export as JSON or .xlsx file
- Excel Spreadsheet output is configured as a sortable table
- Can export as JSON or .xlsx file
Resources
Official
- Cybersecurity Framework | NIST
- Homepage, full document here: nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
- 32 pages long
Supplemental
- Hands on with the NIST Cybersecurity Framework 2.0 w/ Nathan Sweaney - YouTube
- 1 hour long, starts going over the CSF around 22:30
- Excellent short video discussing the new CSF 2.0 framework
- A Tale of Two Frameworks: The NIST CSF and NIST RMF Are Not the Same - Telos Corporation
- Short article
- CertMike Explains NIST Cybersecurity Framework - YouTube
- 5 minutes
- NIST Cybersecurity Framework - YouTube
- Playlist, around 2-hours of content
- Use the NIST Cybersecurity Framework for your Business! - YouTube
- 10 minutes